INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

| 2026-07-21 16:41 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent incident data points indicate a sophisticated and widespread attack on vulnerable WordPress sites, exploiting the "wp2shell" critical vulnerability suite to deploy persistent webshells and install malicious plugins. The attackers have been probing SQL injection attacks to confirm vulnerabilities before delivering PHP webshells, with targeted sectors including finance and healthcare. Automatic security updates were quickly addressed by major software vendors, forcing installations of patched versions on supported sites. Researchers like SearchLight Cyber's Adam Kues have published follow-up reports detailing the exploit chain and developing a working exploit, highlighting the threat level and potential attack vectors. The incident highlights the importance of timely patching, monitoring logs for suspicious activity, inspecting installed plugins, and checking for rogue PHP file additions or newly created admin accounts to mitigate this type of attack.
Technical Mitigations AI-generated
* Regularly update WordPress and plugins: Ensure that all affected versions of WordPress (7.0.2, 6.9.5, and 6.8.6) and installed plugins are up-to-date to prevent exploitation. * Monitor logs for suspicious activity: Regularly review server logs for any unusual or malicious requests related to the wp2shell vulnerabilities. * Implement a web application firewall (WAF): Consider installing a WAF on your WordPress installation to help detect and block potential attacks. * Use secure file inclusion protection: Configure your PHP configuration to prevent local file inclusion attempts, which can be used by attackers to retrieve sensitive data or execute malicious code. * Limit administrator privileges: Restrict administrator access to only necessary features and functions to reduce the attack surface.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

wp•••••.com
ad•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63030CVE-2026-63030 CVE-2026-60137CVE-2026-60137
Target & Sectors
Global Scope
Incident Timeline
‎December 2025
The remote code execution exploit, discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol, allows unauthenticated attackers to gain remote code execution on default WordPress installations in any version released since December 2025.
tactic Remote Code Execution
infrastructure 5.6
organisation GPT
general_metric 5.6 OpenAI Sol
general_metric 10 hours
‎July 17
Threat actors used a vulnerability in WordPress to exploit the site on July 17 within 13 minutes of the security update being issued.
organisation UTC
general_metric 13 minutes
‎Sunday, July 19
VulnCheck discovered and verified more than two-dozen unique PoC exploits targeting WordPress sites via the wp2shell vulnerability as of Sunday, July 19.
organisation VulnCheck
organisation PoC
‎2026/07/20
Threat actors used AI tools to discover and exploit a vulnerability in the WordPress software, allowing them to gain remote access to targeted sites.
‎2026/07/21
Attackers began exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, which allow remote code execution (RCE) on vulnerable sites without authentication.
organisation Dean of Research at Sans Technology Insitute
organisation SQL
organisation PHP
infrastructure 6.8
infrastructure 6.9
organisation RCE
organisation WordPress Core
organisation ClickFix
organisation CVE-2026-60137
organisation GitHub
organisation CMSmap
organisation KB
organisation KEVIntel
organisation IP
infrastructure 13 unique IP addresses
organisation CVE-2026
organisation Cloudflare
organisation API
infrastructure 7.0
infrastructure 7.0.2
infrastructure 6.9.5
infrastructure 6.8.6
organisation WordPress
organisation Abuse of WordPress
organisation Installation of PHP
organisation Querying the WordPress
organisation backtick
organisation UTC
organisation The Hacker News
organisation Administrators of WordPress
organisation EDR
organisation UDF
organisation GPT
organisation Intruder
organisation Google
organisation WatchTowr
organisation Attacker Eye
organisation Golang
infrastructure 6.9.0
infrastructure 6.9.4
infrastructure 7.0.0
infrastructure 7.0.1
organisation WordPress.org
organisation Munch
organisation Cybersecurity
organisation BleepingComputer
Tactical Metrics
Metrics
infrastructure
‎7.0.2
Software Version
Metrics
infrastructure
‎6.9.5
Software Version
Metrics
infrastructure
‎6.8.6
Software Version
Metrics
infrastructure
13
Unique Ip Addresses
Metrics
infrastructure
‎5.6
Software Version
Metrics
infrastructure
‎6.8
Software Version
Metrics
infrastructure
‎6.9
Software Version
Metrics
infrastructure
‎6.9.0
Software Version
Metrics
infrastructure
‎6.9.4
Software Version
Metrics
infrastructure
‎7.0.0
Software Version
Metrics
infrastructure
‎7.0.1
Software Version
Metrics
infrastructure
‎7.0
Software Version